Erlang/OTP 标准库中“输入中指定数量的不当校验”漏洞,允许远程攻击者通过提供一个包含极长数字串作为端口部分的 URI 来降低系统的可用性。 在将端口子串传递给 时未对长度设置上限,且仅捕获 错误。因此,一个语法上合法的、由约 126 位数字组成的端口值可以成功转换,并导致调用进程耗费数百毫秒进行任意精度算术运算。该转换通过 中所有权威部分(authority)解析路径均可触发,包括主机名、注册域名、IPv4 及 IPv6 格式。由于 是解析 URI 的官方文档化接口,任何解析攻击者提供的 URI 的应用程
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71380 | 8.7 HIGH | httpd applies no timeout while receiving a request body, parking a worker on a stalled cli |
| CVE-2026-70399 | 8.7 HIGH | httpd does not enforce the documented default max_clients connection limit |
| CVE-2026-66357 | 8.3 HIGH | inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation |
| CVE-2026-73812 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length |
| CVE-2026-73276 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i |
| CVE-2026-55951 | 8.2 HIGH | httpc memory exhaustion via unbounded response header accumulation |
| CVE-2026-71562 | 6.3 MEDIUM | httpc does not bound server-supplied numeric header values before integer conversion |
No comments yet